ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-07-02
▶The Wire — Daily Briefing

The Wire — Thursday, July 2, 2026

Firewall Breach Becomes Ransomware Accelerant—Security's Convergence Crisis

44 stories analyzed

Firewall Breach Becomes Ransomware Accelerant—Security's Convergence Crisis

The cybersecurity landscape fractured cleanly for years: vulnerabilities were one problem, credential theft another, ransomware a third. Today's threat environment has erased those boundaries. The FortiBleed credential-theft campaign reveals how completely integrated the attack pipeline has become, and enterprises are losing.

Over the past weeks, attackers compromised approximately 110 million credentials from 430,000 FortiGate firewalls worldwide through simple but devastating methods: network scanning to find exposed devices, then credential-guessing attacks coupled with packet sniffing to harvest authentication data. The stolen access isn't sitting in a breach database somewhere. It's being weaponized in real time. Both the INC Ransom and Lynx ransomware groups have confirmed they're deploying this stolen access directly into active ransomware campaigns. Attackers aren't just finding credentials—they're operationalizing them within hours. This is the integration point security leaders have feared for years, and it arrived quietly while everyone was focused elsewhere.

The FortiBleed case reveals something more dangerous than any single vulnerability: a systemic paralysis in network boundary defense. Firewalls represent the outermost perimeter. When 430,000 of them fall to credential-guessing and packet sniffing, it signals that fundamental authentication and network inspection have degraded to theater. FortiGate installations span financial services, healthcare, manufacturing, and government. The compromised credentials grant attackers VPN access, management console control, and network visibility—the keys to everything downstream. Organizations running these devices should assume attackers are already inside their network today.

This convergence extends beyond firewalls. Hackers targeted Microsoft 365 accounts with 81 million login attempts during the same window, exploiting misconfigured Conditional Access Policies that failed to protect the ROPC OAuth flow. The attack bypassed MFA on 78 accounts across 64 organizations. In parallel, 900+ Oracle E-Business Suite instances are actively exploited globally for credential theft and data exfiltration. These aren't isolated incidents—they're symptoms of a coordinated offensive against identity infrastructure itself. Ransomware doesn't need zero-days anymore. It needs valid credentials, and defenders have made that commodity cheap and abundant.

The second crisis unfolding today concerns AI itself. Frontier AI models promised to elevate security defenses. Instead, they're lowering barriers for sophisticated attacks. Researchers documented the first autonomous AI ransomware attack via Langflow exploitation, where an AI agent orchestrated the entire attack lifecycle—reconnaissance, exploitation, lateral movement, data encryption—without human intervention. Separately, InfernoGrabber, an AI-generated ransomware, runs entirely in browsers to steal data and demand ransom, proving that frontier AI models can operationalize previously theoretical threats in weeks, not years.

The vulnerability pipeline has accelerated dramatically. Critical Cursor flaws (DuneSlide, CVSS 9.8) enable prompt injection attacks to escape sandbox and execute arbitrary commands on 50%+ of Fortune 500 machines. Exposed AI inference endpoints are being seized by threat actors for penetration testing and credential theft. And a new threat category emerged: phantom squatting registers domains that AI systems hallucinate during conversations, then hosts phishing sites on them—exploiting AI's tendency to fabricate plausible URLs as new attack infrastructure materializes.

Beyond ransomware and AI, critical infrastructure itself is fracturing. A critical unauthenticated RCE in FUXA SCADA/HMI (CVSS 7.5) exposes user accounts to attackers with no credentials needed—this affects water systems, energy grids, and manufacturing plants globally. An unpatched vulnerability in Argo CD's repo-server allows unauthenticated code execution and Kubernetes cluster seizure with no CVE assigned and no patch available. The DHS confirms hackers breached HSIN, an unclassified security information-sharing platform itself. When the government's threat-intelligence infrastructure becomes a breach victim, defenders lose their ability to coordinate response.

The patch crisis deepens weekly. Adobe patched seven critical flaws in ColdFusion and Campaign Classic (CVSS 10.0, unauthenticated RCE). Apple released critical patches across iOS, macOS, and Safari affecting millions of devices. Citrix patched six NetScaler flaws including HTTP/2 Bomb DoS attacks. Progress Kemp LoadMaster faces active exploitation (CVE-2026-8037, CVSS 9.6) and SharePoint Server RCE (CVE-2026-45659) is under active exploitation today. The velocity of critical patches combined with exploitation-in-the-wild timelines has compressed from days to hours. AI-driven vulnerability discovery is completing in teams what once took months.

Social engineering and supply chain compromise remain the path of least resistance. ClickFix—a social engineering technique that tricks users into executing malicious commands—has become the dominant malware delivery method globally and now targets macOS for the first time. Threat actors have evolved phishing to fingerprint victims' devices and deliver customized OS-specific malware, dramatically increasing infection rates. ChocoPoC masquerades as proof-of-concept CVE exploits on GitHub to target security researchers themselves—the very people tasked with defending others. SEO-poisoned spoofed installers distribute ScreenConnect and AsyncRAT impersonating OBS, DS4Windows, and Bandicam.

The criminal organizations executing these attacks are sophisticated and increasingly transparent. The 19-year-old Scattered Spider suspect extradited to face U.S. charges represents a $100M+ extortion campaign spanning 100+ company breaches. The group operates with operational security that rival nation-states, yet they're being dismantled piece by piece. Meanwhile, large-scale breaches continue: Medtronic disclosed a 9 million-record breach by ShinyHunters, Kubota disclosed month-long access exposing 52,000 employees' data, and Amazon paid $2.25M to settle charges it denied fraud victims access to transaction records.

The convergence is complete. Credential theft feeds ransomware. AI amplifies vulnerability discovery and enables autonomous attacks. Critical infrastructure lacks basic authentication. Patches arrive faster than organizations can deploy them. Social engineering bypasses technical defenses at scale. And the criminal ecosystem operates with the sophistication and coordination of APT groups, yet remains largely decentralized and resilient.

For security professionals, the immediate priority is clear: assume FortiGate compromise, reset all credentials that may have traversed those devices, audit Active Directory and cloud identity platforms for unauthorized access, and isolate any systems where attackers had access. Beyond immediate response, the profession must acknowledge that its century-old model—patching vulnerabilities as they arrive, defending perimeters, hoping employees reject phishing—has structurally failed. The threat velocity, AI amplification, and social engineering dominance demand a reset toward zero-trust architecture, continuous credential rotation, and behavioral anomaly detection rather than signature defense. Microsoft 365 accounts won't protect themselves. Firewalls won't hold. Neither will organizational discipline alone.

Watch for two developments this week: whether FortiBleed becomes the subject of coordinated government response (expect announcements), and whether the AI sandbox escapes (DuneSlide, prompt injection attacks) force enterprise reconsideration of AI tooling at the security perimeter.

Key Takeaways

  • FortiBleed + Ransomware Convergence: 110 million compromised credentials from 430K firewalls are actively weaponized by INC and Lynx ransomware groups. Assume your firewall credentials are compromised if running FortiGate; reset all derivative credentials immediately.
  • AI Amplifies Attack Velocity: From autonomous ransomware agents to prompt-injection sandbox escapes to phantom squatting on hallucinated domains, frontier AI is reducing attack complexity while compressing exploitation windows from weeks to hours.
  • Critical Patch Backlog: Seven CVSS 10.0 flaws, multiple CVSS 9+ vulnerabilities, and unpatched zero-days in Argo CD and Kemp LoadMaster are under active exploitation. Patching cannot keep pace with discovery.
  • Social Engineering Remains Dominant: ClickFix, ChocoPoC, SEO-poisoned installers, and device-specific phishing are outpacing technical defenses. Assume users will click; design around human behavior, not against it.

The Wire is HackWire's daily editorial briefing, published every morning.